firstmerchantsbank[.]at
“First Merchants Bank | Helping You Prosper”
firstmerchantsbank.at — Контент недоступний. Уособлення бренду: MetaMask; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Digi-cloud.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk crypto wallet drainer designed to impersonate MetaMask, a widely used cryptocurrency wallet service. Analysis indicates the site employs brand impersonation techniques to deceive users into disclosing sensitive wallet credentials or executing unauthorized transactions, leading to direct financial theft. The threat type is classified as a crypto wallet drainer due to its focus on extracting digital assets from compromised wallets, rather than generic credential theft or broad phishing tactics. Infrastructure analysis reveals the domain firstmerchantsbank.at was registered on February 21, 2026, through the registrar Digi-cloud, an entity frequently associated with high-risk domains. The domain resolves to the IP address 91.199.163.57, which has been linked to multiple malicious campaigns in recent threat intelligence reports. Detection metrics further corroborate its malicious nature, with 17 out of 95 security vendors on VirusTotal flagging the domain as malicious. The domain appears on three security blocklists and has been assigned a trust score of 0 out of 100 by Gridinsoft. The page title, First Merchants Bank | Helping You Prosper, is a clear attempt to mimic legitimate financial institutions, despite the domain’s primary targeting of MetaMask users. Technologies detected on the site include Nginx, a web server commonly used in both legitimate and malicious infrastructure. Mitigation against this threat requires immediate action from both end users and security teams. Users who may have interacted with the domain should revoke any connected wallet permissions and transfer assets to a new, secure wallet. Security teams are advised to block the domain, its resolving IP address (91.199.163.57), and any associated indicators of compromise at the network perimeter. Organizations should also monitor for unauthorized transactions or wallet access originating from internal networks. Given the domain’s offline status, continuous monitoring for re-registration or re-emergence under a different name is recommended. Awareness campaigns highlighting the risks of crypto wallet drainers and brand impersonation tactics should be prioritized to prevent further victimization.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of firstmerchantsbank.at · checked Jun 27, 2026
Докази та зовнішні звіти
PD-20260207-0C6AF9 Recipient: abuse@digi-cloud.net Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога